PT-2025-8000 · Linux+5 · Linux Kernel+5

Shreeya Patel

·

Published

2022-03-21

·

Updated

2026-04-22

·

CVE-2022-49072

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A race condition issue exists due to the exposure of GPIO chip irq members before they are fully initialized. This can lead to a kernel NULL pointer dereference, as observed with the gc->irq.domain variable accessed through the I2C interface in gpiochip to irq() before initialization by gpiochip add irqchip(). The issue is related to the gpiochip to irq() function and the gc->irq.domain variable.
Recommendations To resolve this issue, restrict the usage of GPIO chip irq members before they are completely initialized. As a temporary workaround, consider disabling the gpiochip to irq() function until a patch is available. Additionally, restrict access to the gc->irq.domain variable to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
BDU:2025-06043
CVE-2022-49072
RHSA-2023:2458
RHSA-2023_2458
USN-8098-1
USN-8098-10
USN-8098-2
USN-8098-3
USN-8098-4
USN-8098-5
USN-8098-6
USN-8098-7
USN-8098-8
USN-8098-9
USN-8107-1
USN-8201-1

Affected Products

Astra Linux
Linuxmint
Linux Kernel
Red Hat
Red Os
Ubuntu